What does the click rate from a phishing simulation campaign measure?
In a phishing simulation exercise, the click rate refers to the percentage of targeted employees who click on the simulated phishing link. This metric is used to gauge how susceptible employees are to social engineering tactics, effectively measuring their level of security awareness and training effectiveness. It does not measure email filtering effectiveness, DLP false-positive rates, or incident response speed — those would be assessed through separate metrics such as email gateway block rates, DLP alert accuracy, or mean time to respond.
Community Discussion